Can anyone guide me to a command or configuration setting within IPS (or wherever it resides) for what Cipher Suites we currently have enabled for HTTPS Inspection?

In a nutshell, we are evaluating TCP Dump data as we are not able to load a particular site on our network. It appears our firewall is sending SSLv3.0 @ Hello and the responding Client, not server, is basically just sending us an SYN ACK back in return that we sent prior to the hello. This site does NOT support anything other then TLS 1.2. We want to confirm our cipher suites for 1.2 have a match with the list we have grabbed from the SSL test we ran on their site.

The command i found on a similar article (i thought) was: cat /opt/CPshrd-R77/registry/HKLM_registry.data | grep -i cptls

HTTPS Inspection negotiations are primarily handled by the wstlsd daemon. Here are the list of cipher suites supported on R80.10 vanilla, pretty sure this will be the same for R77.30. Just because a suite is listed here doesn't necessarily mean that wstlsd permits it to be used by default (case in point: sk110883 - Specific HTTPS sites that use ECDHE ciphers are not accessible when HTTPS Inspection is enabled), but if a cipher suite does not appear in this list I'm pretty sure that means wstlsd won't support it for HTTPS Inspection.

I would imagine these are all valid for TLS 1.2 but I don't know how to verify that. wstlsd does not appear to support "Suite B for TLS 1.2" if that is relevant to your situation.

Dameon Welch Abernathy and @timhall - Cheers for the replies guys. I have already checked out the links you provided Dameon. What I am looking for is a way to confirm what ciphers are allowed through HTTPS on our device, visually in some type of list form. Take note of the list i included in my post about proposing/accept, i would love to know what that is referring to as another post stated this is where you can see what ciphers are accepted or not. @Timhall thanks for the explanation of how https is getting its ciphers. I will continuing reading on this and see if i can make any further progress on this front. Happy Holidays!